Generated by All in One SEO v4.9.6.2, this is an llms.txt file, used by LLMs to index the site. # Wisdiam ## Sitemaps - [XML Sitemap](https://wisdiam.com/sitemap.xml): Contains all public & indexable URLs for this website. ## Posts - [Publications](https://wisdiam.com/publications/) - [11 recent cyber attacks on the water and wastewater sector](https://wisdiam.com/publications/recent-cyber-attacks-water-wastewater/) - This page summarises some of the most recent cyber attacks on water and wastewater utilities that are in the public record. The majority of organisations, of any type, prefer not to publicly report their incidents, so the reality is that more attacks are occurring than we hear about. American Water Date: October 2024Country: United StatesConsequence: - [Enhanced Visibility and Hardening Guidance for Communications Infrastructure](https://wisdiam.com/publications/enhanced-visibility-hardening-guidance-communications-telecom-infrastructure/) - Best practices for improving visibility and hardening communications infrastructure to defend against cyber threats, particularly those linked to PRC-affiliated actors such as Salt Typhoon - [8 recent cyber attacks on food production and agriculture](https://wisdiam.com/publications/recent-cyber-attacks-food-agriculture-sector/) - In this post we highlight cyber incidents that caused operational disruptions, beyond data breaches, to food and agriculture sector entities: Federated Co-op Ltd. (Canada) Duvel Moortgat (Belgium) Farmer Vital Bircher (Switzerland) Campbell Soup Co. (United States) Dole Foods (United States) Super Bock Group (Portugal) Schreiber Foods (United States) JBS (United States and Australia) The attacks - [14 recent cyber attacks on the transport & logistics sector](https://wisdiam.com/publications/recent-cyber-attacks-transport-logistics-sector/) - In this post we summarise recent cyber-attacks on transport and logistics operators. Network Rail (United Kingdom) Transport for London (TfL) (United Kingdom) Port of Seattle (United States) JAS Worldwide (Global) Oahu Transit Services (United States) Baltic Flight Carriers (Baltic Sea, Black Sea, and eastern Mediterranean) Radiant Logistics (United States) Beirut-Rafic Al Hariri International Airport (Lebanon) - [8 recent cyber attacks on the manufacturing industry](https://wisdiam.com/publications/recent-cyber-attacks-manufacturing-industry/) - In the highly competitive world of manufacturing, the intellectual property of competitors can save adversaries millions of dollars, if not billions, in product development, and shrink time to market timelines considerably. The shutdown of production lines can lead to product shortages that result in consumers switching suppliers, as well as starve manufacturers of revenue in - [12 recent cyber-attacks on the telco sector](https://wisdiam.com/publications/recent-cyber-attacks-telcos/) - In this post we summarise recent cyber-attacks on providers of telecommunications services. SFR, Free, Bouygues, and Alphalink (France) AT&T (United States) 2024 metadata breach Frontier Communications (United States) AT&T (United States) Breached 2019; leaked 2024 Edpnet (Belgium) Triacom, Misto TV, Linktelecom and KIM (Ukraine) Tangerine (Australia) Orange España (Spain) Bharat Sanchar Nigam Limited (India) Kyivstar - [GIA's Effective Cyber Risk Management Guide](https://wisdiam.com/publications/governance-institute-of-australias-effective-cyber-risk-management-guide/) - A best practice thought leadership governance guide for digitally secure and resilient organisations - [NIST Cybersecurity Framework (CSF) 2.0](https://wisdiam.com/publications/nist-cybersecurity-framework-csf/) - A globally recognised framework that helps organisations of any size, sector, or maturity, to manage and reduce cyber security risk through a structured, flexible approach - [SA Power Networks Cyber Security Annual Report 2023](https://wisdiam.com/publications/sa-power-networks-cyber-security-annual-report-2023/) - Exemplar cyber security report for boards, executives, asset managers, and external stakeholders - [Four questions boards should ask about domain name security](https://wisdiam.com/publications/questions-boards-ask-about-domain-name-security/) - The humble domain name can be the Achilles heel in an organisation's cyber security - [Two types of e-mail provider to avoid for board business](https://wisdiam.com/publications/avoid-two-e-mail-providers-board-business/) - Company directors using personal e-mail services or accounts belonging to a substantive employer, introduce risks to the company they direct that need to be managed. - [How doughnuts can make or break your cyber security culture](https://wisdiam.com/publications/how-doughnuts-make-break-cyber-security-culture/) - Company context is a critical consideration when implementing and approving quirky initiatives to improve cyber security culture - [Cyber security Exercise in a Box guided tour](https://wisdiam.com/publications/cyber-security-exercise-in-a-box-guided-tour/) - Tabletop exercises are an effective and practical way to work with management and other stakeholders to simulate responding to a cyber incident. - [Cyber-Informed Engineering (CIE) vs Consequence Driven, Cyber-Informed Engineering (CCE)](https://wisdiam.com/publications/cie-vs-cce/) - Cyber-Informed Engineering (CIE) and Consequence Driven, Cyber-Informed Engineering (CCE) are concepts developed by the Idaho National Laboratory (INL). A side-by-side comparison of the two is presented in the table below. CIE is a guide to embedding cyber security considerations into cyber-physical systems throughout the engineering lifecycle model, and across business functions. The CIE guide is - [Rare look into city council cyber attack and consequences](https://wisdiam.com/publications/city-council-cyber-attack-consequences/) - Gloucester City Council's ransomware attack case study provides insights and lessons for many - [One PC from disaster: Zaun's cyber security lesson](https://wisdiam.com/publications/one-pc-from-disaster-zaun-cyber-security-lesson/) - A UK-based manufacturer of security fencing recently found itself targeted by a Russia-linked ransomware group who managed to exfiltrate data from their systems. Given the company's clientele, which includes British government entities*, the fact that the attackers failed to encrypt their systems is a matter of little consequence. This incident highlights several pertinent issues that - [Insights from a rare case study](https://wisdiam.com/publications/insights-from-rare-case-study/) - An asset-rich organisation, Gloucester City Council uses suppliers to help maintain service delivery. Just as many asset management organisations do. In 2021 they suffered a ransomware attack that presented via an email, mid-conversation, from a supplier that had themselves been compromised. In 2023, the Local Government Association, in collaboration with the council, published a case - [Let's torque about smart tool cyber security](https://wisdiam.com/publications/lets-torque-about-smart-tool-cyber-security/) - Vulnerabilities found with a smart tool highlight some of the risks of relying on technology for critical operations - [Cyber-Physical Systems](https://wisdiam.com/publications/cyber-physical-systems/) - Cyber-physical systems are a type of system where physical processes and computational elements are deeply integrated and interact with each other - [AICD's Governing Through a Cyber Crisis](https://wisdiam.com/publications/aicd-governing-through-cyber-crisis/) - A framework for cyber incident preparedness, response and recovery for Australian directors - [Manufacturing under cyber-attack](https://wisdiam.com/publications/manufacturing-under-cyber-attack/) - Cyber incidents were publicly reported at two manufacturing companies over the past few weeks. This comes as cyber security company Dragos reported it had tracked a 50% increase in ransomware attacks against industrial companies in 2023, with manufacturing accounting for 71% of all ransomware attacks. Varta batteries was attacked on 12 February 2024, and steel - [Hacktivists tap into vulnerable operational technology](https://wisdiam.com/publications/hacktivists-tap-into-vulnerable-operational-technology/) - Proving that money and target size aren’t the primary concern for all hackers, a cyber attack by hacktivists on water equipment in the western Ireland area of Erris, County Mayo, left 160 households without a supply for two days [The Record. 12 December 2023]. Hacktivists value impact and headlines over money to promote a political - [CISC's Overview of Cyber Security Obligations for Corporate Leaders](https://wisdiam.com/publications/ciscs-overview-of-cyber-security-obligations-for-corporate-leaders/) - Guide to obligations and requirements for critical infrastructure asset cyber security frameworks - [Unlocking Cyber Resilience in Industrial Environments: 5 Principles](https://wisdiam.com/publications/unlocking-cyber-resilience-industrial-environments-five-principles/) - Five guiding principles with actionable implementation approaches for cyber resilient operational technology environments - [How boards can protect the security of employee information](https://wisdiam.com/publications/how-boards-can-protect-security-employee-information/) - Employee data can be exceptionally sensitive and deserves special attention from a cyber security perspective - [New course: Cyber security for infrastructure asset managers](https://wisdiam.com/publications/new-course-cyber-security-infrastructure-asset-managers/) - Essential Cyber Security Awareness for Infrastructure Asset Managers, due late 2023, is an indispensable eLearning course specifically designed for professionals involved in asset-intensive industries. A comprehensive course, it will equip builders, managers, maintainers, and service providers with essential cyber security knowledge and skills to mitigate cyber threats and safeguard infrastructure organisations. Tailored for asset-intensive industries: - [NCSC's Cyber Security Training for Staff](https://wisdiam.com/publications/ncscs-cyber-security-training-for-staff/) - Free cyber security e-learning for small to medium sized businesses, charities and the voluntary sector - [NCSC's Cyber Security Toolkit for Boards](https://wisdiam.com/publications/ncsc-cyber-security-toolkit-for-boards/) - Resources designed to encourage essential cyber security discussions between the Board and their technical experts - [Directors: How to get to know your critical digital assets](https://wisdiam.com/publications/how-to-know-your-critical-digital-assets/) - Knowing your critical digital assets can be as important as knowing your critical financial numbers - [AICD's Cyber Security Governance Principles](https://wisdiam.com/publications/aicd-cscrc-cyber-security-governance-principles/) - A framework for effective board oversight of cyber security across five key areas - [Building a Model of Organisational Cybersecurity Culture](https://wisdiam.com/publications/building-a-model-of-organisational-cybersecurity-culture/) - Paper describing organisational cybersecurity culture, the factors that contribute to its creation, and how it can be measured ## Pages - [Cyber security awareness for infrastructure asset managers](https://wisdiam.com/) - Cyber security insights, news, tips, and resources for infrastructure asset managers. From directors and executives, to risk managers, engineers and operations. - [About Wisdiam](https://wisdiam.com/about/) - Driving cyber resilience across asset-intensive infrastructure organisations through education and information services - [Cyber security awareness that gets noticed](https://wisdiam.com/subscribe/corporate/) - … direct to where your people receive their most important communications—the email inbox. You can’t educate your staff on threats that are evolving every day, using an annual eLearning module For a start, a lot of eLearning is boring, unrealistic, and incredibly childish. So not a lot sinks in. And for many it’s treated as - [Cyber Security Resources for Leaders in Asset Management](https://wisdiam.com/resources/) - Useful resources to help company directors, executives and leaders of asset-intensive organisations manage cyber risk. Enhanced Visibility and Hardening Guidance for Communications Infrastructure Best practices for improving visibility and hardening communications infrastructure to defend against cyber threats, particularly those linked to PRC-affiliated actors such as Salt Typhoon GIA’s Effective Cyber Risk Management Guide A best - [Privacy Policy](https://wisdiam.com/privacy-policy/) - Last updated: 11 January 2024 This Privacy Policy describes Our policies and procedures on the collection, use and disclosure of Your information when You use the Service and tells You about Your privacy rights and how the law protects You. We use Your Personal data to provide and improve the Service. By using the Service, - [Contact](https://wisdiam.com/contact/) - Complete the following form to send an enquiry. Please leave this field empty. Your email Your query Please leave this field empty. ## Categories - [Resources](https://wisdiam.com/topics/resources/) - [Updates](https://wisdiam.com/topics/updates/) - [Personal Accountability](https://wisdiam.com/topics/accountability/) - [Culture](https://wisdiam.com/topics/culture/) - [Tips](https://wisdiam.com/topics/tips/) - [Commentary & Insights](https://wisdiam.com/topics/commentary/) - [Explain](https://wisdiam.com/topics/explain/)